an attacker to utilize password-less user accounts and obtain
system access by activating a reverse shell.This issue affects MTC-9: from R22.1.1.0275 before R23.0.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.cvcn.gov.it/cvcn/cve/CVE-2025-27019 |
|
Mon, 22 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nokia
Nokia infinera Mtc-9 Nokia infinera Mtc-9 Firmware |
|
| CPEs | cpe:2.3:h:nokia:infinera_mtc-9:-:*:*:*:*:*:*:* cpe:2.3:o:nokia:infinera_mtc-9_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Nokia
Nokia infinera Mtc-9 Nokia infinera Mtc-9 Firmware |
Tue, 09 Dec 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Infinera
Infinera mtc-9 |
|
| Vendors & Products |
Infinera
Infinera mtc-9 |
Mon, 08 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Dec 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system access by activating a reverse shell.This issue affects MTC-9: from R22.1.1.0275 before R23.0. | |
| Title | Remote shell service (RSH) in Infinera MTC-9 | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2025-12-08T17:27:47.739Z
Reserved: 2025-02-18T06:59:55.888Z
Link: CVE-2025-27019
Updated: 2025-12-08T17:27:42.104Z
Status : Analyzed
Published: 2025-12-08T10:16:01.270
Modified: 2025-12-22T18:55:45.403
Link: CVE-2025-27019
No data.
OpenCVE Enrichment
Updated: 2025-12-09T10:26:39Z